CVE-2022-1613: Restricted Site Access < 7.3.2 - Access Bypass via IP Spoofing
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTEADDR, which makes it possible to bypass IP-based limitations in certain situations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1613?
CVE-2022-1613 is rated as a high severity vulnerability due to the potential for IP-based access control bypass.
How do I fix CVE-2022-1613?
To fix CVE-2022-1613, update the Restricted Site Access WordPress plugin to version 7.3.2 or later.
Who is affected by CVE-2022-1613?
WordPress sites using versions of the Restricted Site Access plugin before 7.3.2 are affected by CVE-2022-1613.
What does CVE-2022-1613 allow an attacker to do?
CVE-2022-1613 allows an attacker to bypass IP-based restrictions by exploiting how the plugin retrieves visitor IP addresses.
When was CVE-2022-1613 disclosed?
CVE-2022-1613 was disclosed in 2022 and affects earlier versions of the Restricted Site Access plugin.